CWE-119

High likelihood

Improper Restriction of Operations within the Bounds of a Memory Buffer

Parent: CWE-118 - Incorrect Access of Indexable Resource ('Range Error')

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

13,986 vulnerabilities with CWE-119
CVE-2019-8396 MEDIUM
HDF5 < 1.10.4 - Denial of Service via Crafted HDF5 File
CVSS 6.5
CVE-2019-8383 HIGH
advancecomp < 2.1 - Denial of Service via Invalid Memory Access in adv_png_unfilter_8
CVSS 7.8
CVE-2019-8381 HIGH
Tcpreplay 4.3.1 - Denial of Service via Crafted PCAP File in do_checksum
CVSS 7.8
CVE-2019-6541 HIGH
WECON LeviStudioU <= 1.8.56 - Memory Corruption
CVSS 7.8
CVE-2019-1651 CRITICAL
Cisco vSmart Controller - Authenticated Remote Code Execution and Denial of Service via Malicious File Upload
CVSS 9.9
CVE-2019-1641 HIGH
Cisco Webex Network Recording Player and Webex Player - Remote Code Execution via Malicious ARF or WRF File
CVSS 7.8
CVE-2019-1640 HIGH
Cisco Webex Network Recording Player and Webex Player - Remote Code Execution via Malicious ARF or WRF File
CVSS 7.8
CVE-2019-1639 HIGH
Cisco Webex Network Recording Player and Webex Player - Remote Code Execution via Malicious ARF or WRF File
CVSS 7.8
CVE-2019-1638 HIGH
Cisco Webex Network Recording Player and Webex Player - Remote Code Execution via Malicious ARF or WRF File
CVSS 7.8
CVE-2019-1637 HIGH
Cisco Webex Network Recording Player and Webex Player - Remote Code Execution via Malicious ARF or WRF File
CVSS 7.8
CVE-2018-25109 MEDIUM
Nintendo Animal Crossing <1.01 - Memory Corruption
CVSS 6.4
CVE-2018-25042 MEDIUM
uTorrent - Remote Code Execution via Memory Corruption
CVSS 5.0
CVE-2018-21052 CRITICAL
Android N(7.x) and O(8.x) - Arbitrary Code Execution via Vaultkeeper Trustlet Shared Memory
CVSS 9.8
CVE-2018-21027 CRITICAL
Boa < 0.94.14.21 - Denial of Service via Memory Allocation Mishandling
CVSS 9.8
CVE-2018-5732 HIGH
ISC DHCP <4.1-ESV-R15, 4.2.8, 4.3.6, 4.4 - Buffer Overflow
CVSS 7.5
CVE-2018-11768 HIGH
Apache Hadoop 2.0.0-2.9.1, 3.0.0-3.0.3, 3.1.0-3.1.1 Memory Corruption
CVSS 7.5
CVE-2018-20998 CRITICAL
arrayfire < 3.6.0 - Memory Corruption via Enum repr() Attribute Mishandling
CVSS 9.8
CVE-2018-20995 CRITICAL
slice-deque < 0.1.16 - Memory Corruption via move_head_unchecked
CVSS 9.8
CVE-2018-21000 CRITICAL
safe-transmute < 0.10.1 - Heap Memory Corruption via Constructor Argument Order
CVSS 9.8
CVE-2018-20855 LOW
Linux Kernel < 4.18.7 - Information Disclosure via Uninitialized Stack Memory in mlx5_ib_create_qp_resp
CVSS 3.3
CVE-2018-7838 HIGH
Schneider Electric Modicon M580 and BMENOC0301 - Denial of Service via FTP CWD Command
CVSS 7.5
CVE-2018-11425 CRITICAL
Moxa OnCell G3470A-LTE Series < 1.6 - Memory Corruption
CVSS 9.8
CVE-2018-11423 HIGH
Moxa OnCell G3150-HSPA Firmware < 1.6 - Memory Corruption
CVSS 7.5
CVE-2018-15519 CRITICAL
Lexmark CX/CX/XC/MX/XM Firmware < lw70 - Buffer Overflow
CVSS 9.8
CVE-2018-15520 CRITICAL
Lexmark CX/CX/CX/XC/MX/MB Firmware < 052.024 - Buffer Overflow
CVSS 9.8
Details
Vulnerabilities 13,986
Exploit Likelihood High